Cross-Organization Threat Discovery via Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security threat detection systems face challenges in accurately identifying malicious attacks, particularly when covert techniques are employed, leading to a high number of false positive alerts due to low fidelity indicators of compromise, which require costly manual analysis and hinder effective threat detection across various organizations.

Innovation Solution

A system and method that utilize clustering and similarity analysis of security data to generate risk scores for potential attacks, incorporating indicators of compromise, forensic information, and additional clustering information to identify and predict new threats, while dynamically updating indicators and scores based on new data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If low fidelity indicators of compromise are used to detect covert cyber-attacks, then the ability to detect malicious attacks is improved, but the number of false positive alerts increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent combines multiple low fidelity indicators of compromise from multiple organizations into a collective intelligence system. By merging data across organizational boundaries and applying clustering algorithms, the system transforms individual low-fidelity signals into high-fidelity threat detections through pattern recognition across the collective dataset.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback loops where detected threats and false positives are used to continuously refine the clustering algorithms and indicator weighting. The collective intelligence system learns from each detection event, adjusting fidelity scores and detection thresholds to improve accuracy over time while reducing false positives.

Inventive Principle:
Principle #23Feedback

2Device complexity

If traditional indicator of compromise analysis is used, then individual organization security monitoring is simplified, but the ability to detect coordinated attacks across organizations is reduced

Engineering Contradiction:
Improvesecurity monitoring complexityVSAvoidcross-organization threat detection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent creates a universal security monitoring platform that serves multiple organizations simultaneously. The collective intelligence system performs multiple functions: individual organization monitoring, cross-organization pattern detection, threat correlation, and predictive analytics, all through a single multi-functional architecture that benefits all participants.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system adds a new dimension to security monitoring by transitioning from single-organization isolated analysis to multi-organization collective intelligence. This dimensional shift enables detection of coordinated attacks that span multiple organizations by analyzing patterns across the expanded organizational landscape.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If manual analysis of security alerts is performed, then false positive alerts can be investigated, but the cost and time required for threat analysis increases

Engineering Contradiction:
Improvealert verification accuracyVSAvoidthreat analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The collective intelligence system performs self-service by automatically analyzing and correlating indicators of compromise across organizations without requiring manual intervention. The clustering algorithms and predictive analytics engines autonomously process security data, identify threats, and generate detections, eliminating the need for manual false positive investigation while maintaining high accuracy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11044263B2Systems and methods for threat discovery across distinct organizations
Publication Date: 2021.06.22 SOPHOS INC
  • US11044263B2 patent drawing
  • US11044263B2 patent drawing
  • US11044263B2 patent drawing

AI summary

The present disclosure provides systems and methods for organizations to use security date to generate a risk scores associated with potential compromise based on clustering and/or similarities with other organizations that have or may have been compromised. For example, indicators of compromise can be used to create a similarity score rank over time that may be used as a similarity and risk measurement to generate a continual/dynamic score, which can change and/or be updated as new data is created or arrives to detect or prevent threats and/or malicious attacks.